#YellowKey
After getting the YellowKey and returning to the two doors, yellow says he can't get into "the ol' yeller room." Which is a reference to the Western drama film Old yeller, which ends with the titular dog being put down like Yellow plans to be.
September 6, 2026 at 1:07 PM
It's one yellowkey George, how much impact can it have?
March 15, 2026 at 8:35 PM
A good primer on the new Bitlocker exploit. solcyber.com/bitlocker-in...
BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber
Nightmare Eclipse hates Microsoft, loves dropping 0-days.
solcyber.com
May 17, 2026 at 8:39 PM
Microsoft BitLocker drives can be accessed using a USB stick with certain files due to the YellowKey zero-day exploit, which suggests the presence of a backdoor.
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
View post on Reddit.
reddit.com
May 13, 2026 at 5:42 PM
I really have no time with man-children who have no professional courtesy. But for followers’ information and not his, the YellowKey backdoor requires holding the Ctrl key during the WinRE startup sequence. That shows a specific intent.
You made a specific claim of intent. This doesn't support the conclusion you made.
May 24, 2026 at 9:24 PM
I think this 'Nightmare-Eclipse/YellowKey' thing a big dumb nothingburger that doesn't actually give you decrypted access to the bitlocker volume. Their screenshot here github.com/Nightmare-Ec... is just of the recovery tools running in the X: ramdisk, not of the decrypted volume,
GitHub - Nightmare-Eclipse/YellowKey: YellowKey Bitlocker Bypass Vulnerability
YellowKey Bitlocker Bypass Vulnerability. Contribute to Nightmare-Eclipse/YellowKey development by creating an account on GitHub.
github.com
May 14, 2026 at 2:02 PM
Microsoft has released patches for the zero-day vulnerabilities named YellowKey, GreenPlasma, and MiniPlasma. These updates address critical security flaws, ensuring user protection against potential exploits.
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
View post on Reddit.
reddit.com
June 10, 2026 at 8:42 PM
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives.
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives.
www.bleepingcomputer.com
May 20, 2026 at 7:31 AM
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585
Exploit
thehackernews.com/2026/05/micr...
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Microsoft released mitigations for YellowKey, a publicly disclosed BitLocker bypass tracked as CVE-2026-45585 with a CVSS score of 6.8.
thehackernews.com
May 21, 2026 at 11:20 AM
YellowKey MSFT Bitlocker bypass (backdoor?) and GreenPlasma LPE POC #infosec

deadeclipse666.blogspot.com
Chaotic Eclipse
deadeclipse666.blogspot.com
May 14, 2026 at 4:52 AM
Mystery Microsoft bug leaker keeps the zero-days coming
Mystery Microsoft bug leaker keeps the zero-days coming
Security pros warn YellowKey claim could make stolen laptops a much bigger problem
www.theregister.com
May 13, 2026 at 4:18 PM
Der IT-Forscher hinter dem „NightmareEclipse“-Projekt zeigt neue Lücken: „YellowKey“ in BitLocker und Rechteausweitung mit „MiniPlasma“. #Security
Windows-Sicherheitslücken: BitLocker-Problem und Rechteausweitung
Der IT-Forscher hinter dem „NightmareEclipse“-Projekt zeigt neue Lücken: „YellowKey“ in BitLocker und Rechteausweitung mit „MiniPlasma“.
www.heise.de
May 18, 2026 at 11:26 AM
Mystery Microsoft bug leaker keeps the zero-days coming
Mystery Microsoft bug leaker keeps the zero-days coming
Security pros warn YellowKey claim could make stolen laptops a much bigger problem
www.theregister.com
May 16, 2026 at 12:20 AM
It would have been a smarter move to permanently fix the YellowKey backdoor and acknowledge this hunter's work
Microsoft has banned Nightmare Eclipse from GitHub: github.com/Nightmare-Ec...

This is the researcher who disclosed several zero-days after Microsoft also deleted his MSRC account

They now moved on GitLab: deadeclipse666.blogspot.com
May 24, 2026 at 3:15 PM
Microsoft’s June Patch Tuesday closes an intentional BitLocker backdoor in Windows 11.
🔗 www.windowscentral.com/microsoft/wi...
Windows 11’s June Patch Tuesday closes an intentional BitLocker backdoor — what to know
Microsoft just patched YellowKey, GreenPlasma, and MiniPlasma as part of its June 2026 Patch Tuesday update.
www.windowscentral.com
June 10, 2026 at 7:01 PM
Nightmare Eclipse has released Greenplasma and YellowKey on GitHub. Greenplasma is a Local Privilege Escalation (LPE), though not a full Proof of Concept (PoC), while YellowKey is a Bitlocker bypass.
Nightmare Eclipse has published Greenplasma and YellowKey
One is an LPE (but not full PoC), the other is a Bitlocker bypass. https://github.com/Nightmare-Eclipse
reddit.com
May 13, 2026 at 12:42 AM
A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
Windows BitLocker zero-day gives access to protected drives, PoC released
A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
www.bleepingcomputer.com
May 13, 2026 at 4:38 PM
[ACTU] Une nouvelle faille de sécurité visant BitLocker. Un chercheur a publié un exploit Proof of Concept (PoC) baptisé « YellowKey » qui permettrait de contourner la protection BitLocker sur certains systèmes Windows 11 et Windows Server.

La suite 👇

www.malekal.com/une-faille-b...
www.malekal.com
May 16, 2026 at 7:21 AM
Zero-Day Exploit Against Windows BitLocker

It's nasty, but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the…
Zero-Day Exploit Against Windows BitLocker
It's nasty, but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments. Slashdot thread. And here's Nightmare-Eclipse's GitHub account.
www.schneier.com
May 18, 2026 at 11:09 AM
Microsoft BitLocker – YellowKey zero-day exploit | Discussion
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
Also, it's a twofer with the GreenPlasma zero-day local privilege escalation.
www.tomshardware.com
May 14, 2026 at 5:20 AM
On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives.
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives.
www.bleepingcomputer.com
June 10, 2026 at 9:57 AM